Privacy notice
This notice explains how AaltoAI ry processes personal data about members, account holders, programme participants and visitors to aaltoai.com.
Last updated 25 August 2026
1. Controller and contact details
AYY (Housing), P.O. Box 69
02150 Espoo, Finland
Privacy questions and requests may be sent to team@aaltoai.com.
2. Scope and registers
This notice covers the association's membership records, website accounts and public profiles, projects, programme and hackathon participation, newsletter subscriptions, support messages and the technical information needed to operate and protect the website.
A separate notice may apply where a programme collects additional information. For example, the AaltoAI / Safety Fellowship has its own applicant privacy statement.
3. Personal data we process
- Account data: name, username, email address, authentication identifiers and account metadata. Password authentication is handled by Supabase Auth; AaltoAI does not receive passwords in plain text.
- Profile data: name, username, biography, skills and optional GitHub and LinkedIn links.
- Membership data: first and last name, address, city of residence, date of birth, optional gender, phone number, AYY membership status, membership category and membership dates.
- Community activity: projects, applications for partner services, project roles, programme registrations, team memberships, submissions and content provided through those services.
- Communications: newsletter email address and the name, email address and message submitted through support or other forms.
- Technical data: authentication and preference cookies, IP address, truncated user-agent information, timestamps, request logs and security or rate-limit records.
- AI assistant data: questions sent to the assistant and the technical identifiers used to prevent abuse. Please do not submit sensitive personal data to the assistant.
4. Purposes and legal bases
We process personal data only where there is a lawful basis:
- to maintain membership records, administer the association and meet legal or accounting obligations;
- to create accounts and provide the projects, events, programmes and support requested by a user;
- to operate the community, communicate with members and participants, and protect the website and its users, based on AaltoAI's legitimate interests;
- to publish profile, project and submission information that a user chooses to make public; and
- to send the newsletter on the basis of consent. Consent may be withdrawn at any time.
Depending on the activity, the legal basis is consent (GDPR Article 6(1)(a)), performance of a contract or steps requested by the individual (Article 6(1)(b)), compliance with a legal obligation (Article 6(1)(c)), or AaltoAI's legitimate interests in running and securing its activities (Article 6(1)(f)).
5. Sources and public information
Most information is received directly from the individual through account, membership, project, programme, newsletter and contact forms. If a person chooses Google or GitHub sign-in, basic account information is received from that provider. Technical data is generated when the website and its services are used.
Public profiles may display a name, username, biography, skills and external profile links. Public projects and submissions may display their content and the usernames of contributors. Membership details, email addresses and dates of birth are not made public.
6. Recipients and service providers
Access within AaltoAI is limited to authorised people who need the information for the purposes described above. We do not sell personal data.
The website currently uses the following service-provider categories:
- Supabase for authentication, database and file storage;
- Vercel for website hosting and operational delivery;
- Google for reCAPTCHA and optional Google sign-in;
- GitHub for optional GitHub sign-in;
- Resend for messages sent through the support form;
- OpenAI for responses generated by the AI assistant; and
- Upstash for AI-assistant rate limiting and related operational statistics.
These providers process data on AaltoAI's behalf or, for optional third-party sign-in, under the provider's own terms. Personal data may also be disclosed where required by law or necessary to establish, exercise or defend legal claims.
7. International transfers
Some providers or their subprocessors may process personal data outside the European Union or European Economic Area. Where this occurs, transfers must rely on an applicable European Commission adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Further information about applicable safeguards is available from AaltoAI on request.
8. Retention
- Membership information is kept for the duration of membership and afterwards only as long as required for statutory administration, accounting or legal claims.
- Account and profile data are kept while the account is active. Related content is removed or retained according to ownership, public-project and legal requirements when an account is deleted.
- Newsletter addresses are kept until the person unsubscribes or requests removal.
- Support and programme communications are kept until the matter has been handled and the information is no longer reasonably needed.
- The cookie-preference choice lasts up to 365 days. Authentication cookies follow the session duration set by the authentication service.
- Unauthenticated AI-assistant rate-limit identifiers may be retained for up to 999 days under the current abuse-prevention configuration. Other technical logs are kept only as long as reasonably necessary for security and service operation.
Information may be deleted or anonymised earlier when it is no longer needed. Backups may retain data for a limited additional period before being overwritten.
9. Cookies and online services
Essential cookies support authentication, remember the cookie choice and preserve user interface preferences. The cookie banner stores either all or essentialfor up to 365 days. AaltoAI does not currently use advertising or visitor-analytics cookies.
Google reCAPTCHA protects the newsletter form and may process device, browser and network information under Google's terms. The AI assistant processes a submitted question and related technical information through OpenAI and Upstash only when that service is used.
10. Security
We use access controls, encrypted connections, database row-level security and other appropriate technical and organisational measures. Access is limited to people whose responsibilities require it. No online service can be guaranteed completely secure, but suspected incidents are investigated and handled in accordance with applicable law.
11. Your rights
Subject to the conditions in the GDPR, an individual may:
- request access to and a copy of their personal data;
- request correction or completion of inaccurate data;
- request erasure or restriction of processing;
- object to processing based on legitimate interests;
- receive data in a portable format where the right applies; and
- withdraw consent at any time without affecting earlier lawful processing.
Send a request to team@aaltoai.com. We may need to verify the requester's identity and normally respond within one month. You may also lodge a complaint with the Office of the Data Protection Ombudsman.
12. Automated decision-making
AaltoAI does not use the personal data covered by this notice for automated decisions or profiling that produce legal or similarly significant effects. The website's AI assistant generates informational responses but does not make decisions about users.